
World Leaks Ransomware Expands Its Victim List with Tata and Reliance-Linked NPCIL in India
Executive Summary
World Leaks, launched on January 1, 2025, is a data-extortion group and rebrand of the former Hunters International RaaS operation, which shut down in November 2024. It follows an exfiltration-first model, stealing and leaking sensitive data instead of encrypting systems. The group has claimed over 170 victims across 29 countries and recently increased targeting of Indian entities, including a disclosure linked to the Kudankulam Nuclear Power Project through a contractor server hosted by Yotta.
Threat Profile
Group Overview
World Leaks is a data-extortion-focused threat group that operates using:
- Data exfiltration as the primary attack objective
- Direct extortion against victims via negotiation portal and live chat
- Public disclosure through a TOR-based leak site
- A journalist "Insider" early-access program to intensify reputational pressure
The group is a direct rebrand of Hunters International. Hunters International's operators announced the closure of that project on November 17, 2024, citing that ransomware had become too risky and unprofitable due to law enforcement pressure and geopolitical conditions. On January 1, 2025, the same operators relaunched under the World Leaks name with an explicit "no encryption" positioning. Researchers assess this as a rebrand with high confidence, based on reuse of the predecessor's exfiltration tooling, a near-identical affiliate panel and leak-site layout, and continuity of operators and negotiation methodology. The group has publicly denied collaboration with other threat actors and has issued impersonation warnings directing victims to verify contact only through its own listed onion addresses.
Operational Characteristics
World Leaks runs an Extortion-as-a-Service (EaaS) affiliate model built around a proprietary data-exfiltration tool rather than an encryption payload, marking a deliberate departure from its predecessor's ransomware structure.

Victimology
Overview
|
Metric |
Value |
|
Total Victims |
173 |
|
Countries Affected |
29 |
|
Active Since |
January 2025 |
|
Leak Site |
Active |
World Leaks has sustained a steady operational cadence since relaunch, briefly interrupted by an early-2025 infrastructure stability issue that delayed its first published victim to late April 2025. Since then, listing activity has been consistent, with a marked increase in high-profile disclosures through mid-2026.
The victim set spans small and mid-sized firms as well as large multinational institutions, including automotive and electronics manufacturers, financial-services subsidiaries, healthcare networks, public-sector bodies, and critical-infrastructure-adjacent contractors. This variation suggests targeting driven by accessible entry points and data value rather than a fixed size or sector preference.
Geographical Distribution
World Leaks exhibits a broad but unevenly weighted victim footprint, with strong dominance in the United States alongside an expanding international presence.

World Leaks exhibits a broad but unevenly weighted victim footprint, with strong dominance in the United States alongside an expanding international presence. The United States represents the primary concentration of victims (91 victims), significantly outweighing all other regions. The next most affected countries are the United Kingdom (10), Brazil (8), Germany (8), Canada (7), and India (7), followed by Japan (5) and Taiwan (4). Additional, lower-volume activity spans Italy, Spain, France, Switzerland, Belgium, Indonesia, Mexico, Pakistan, Sweden, Thailand, Sri Lanka, Hungary, China, Denmark, Finland, Singapore, Serbia, Australia, Colombia, Cameroon, and Romania. This distribution indicates that while the group is not geographically restricted, a discernible regional cluster has formed around Indian manufacturing, energy, and critical-infrastructure-adjacent contractors in recent months, rather than isolated opportunistic hits.
Sector Targeting

World Leaks' sector distribution reflects broad, opportunistic targeting rather than a single-industry focus, with the heaviest concentration in healthcare, followed by manufacturing and industrial production, business and professional services, technology and electronics, and consumer services. Financial services, construction, and education follow at roughly comparable levels, with energy, transportation/logistics, hospitality, and agriculture/food production forming a smaller but recurring tier. Retail, consumer goods, and public-sector or critical-infrastructure-adjacent contractors round out a broader but less frequent target set. This spread indicates that targeting is shaped primarily by exposed entry points and data value rather than a narrow vertical preference.
Technical Analysis
Initial Access and Foothold:
Recent victim disclosures and publicly reported incidents indicate that World Leaks primarily gains initial access through compromised credentials targeting internet-facing VPNs, remote-access services, and externally exposed applications. Opportunistic exploitation of vulnerable public-facing systems and phishing campaigns remain secondary access vectors. The group's operations continue to demonstrate a preference for exploiting weak identity security and externally accessible infrastructure over the use of zero-day exploits.
The increasing concentration of victims across Indian manufacturing, financial services, and critical-infrastructure supply chains suggests deliberate targeting of organizations with high-value intellectual property, engineering documentation, supplier information, and operational records that can maximize extortion leverage after compromise.
Privilege Escalation, Defense Evasion, and Persistence:
Persistence is commonly achieved through scheduled tasks, Registry Run key modifications, and abuse of legitimate administrative utilities following successful compromise.
Defense evasion techniques include credential theft, selective log manipulation, masquerading of malicious processes as legitimate system activity, and the abuse of trusted Windows components to reduce detection. The group relies heavily on PowerShell and Windows command-line interpreters to perform post-compromise operations while minimizing reliance on custom malware.
Lateral Movement and Exfiltration:
Lateral Movement
World Leaks primarily performs lateral movement using valid domain accounts together with SMB and Windows administrative shares, supplemented by limited Remote Desktop Protocol (RDP) usage. Current reporting does not indicate consistent deployment of sophisticated lateral movement frameworks, with operators instead favoring legitimate administrative access and native Windows functionality.
Attack Sequence
- Initial compromise through exposed VPNs, remote-access infrastructure, compromised credentials, or vulnerable internet-facing applications.
- Execution using PowerShell and Windows command-line utilities.
- Internal reconnaissance, credential harvesting, and privilege expansion.
- Discovery and collection of engineering documents, financial records, intellectual property, supplier data, and business-critical information.
- Staging of collected data within the victim environment.
Automated exfiltration to attacker-controlled infrastructure through the proprietary World Leaks exfiltration platform.
Extortion through the TOR-based negotiation portal, leak site, searchable file explorer, and Insider journalist early-access program.
Data Exfiltration
Data exfiltration represents the group's primary operational objective. Affiliates are provided with a proprietary exfiltration client that automates file discovery, indexing, and transfer through SOCKSv5 proxies over the TOR network. Stolen datasets typically remain on affiliate-controlled infrastructure until negotiations conclude, after which selected files or complete datasets may be published through the World Leaks leak portal. Recent disclosures involving Tata Electronics (~630 GB), Reliance Infrastructure (~1.2 TB), and other Indian organizations demonstrate the group's capability to exfiltrate large volumes of sensitive enterprise data.
Encryption
World Leaks publicly markets itself as an extortion-only operation that does not routinely deploy ransomware encryption. Most documented incidents involve data theft without encrypted-file artifacts. However, inherited capabilities from the Hunters International codebase indicate that encryption functionality remains available, and at least one confirmed 2026 incident involved ransomware deployment. Consequently, organizations should not assume encryption capability is absent during future intrusions.
Command and Control (C2):
Available intelligence indicates that World Leaks operates a centralized TOR-based infrastructure consisting of a leak site, negotiation portal, affiliate management panel, and Insider journalist portal. Command-and-control and exfiltration communications are conducted through attacker-controlled infrastructure utilizing TOR and multi-hop proxy mechanisms. Public reporting provides limited protocol-level details beyond the use of anonymized communication channels and dedicated onion services for victim negotiations and affiliate operations.
Communication and Platform Analysis
World Leaks operates a four-part infrastructure: a TOR-hosted leak site with a searchable file explorer, a victim negotiation portal with live chat and Bitcoin-only payment tracking, an affiliate management panel, and an "Insider" journalist portal granting media outlets roughly 24-hour advance access to newly disclosed data ahead of public release.
The group has publicly addressed impersonation attempts, stating that its only legitimate contact points are its own listed onion addresses, and has denied formal partnerships with other groups — a claim in tension with observed shared leak-site infrastructure with at least one other extortion operation.
Negotiation Behavior
World Leaks follows a structured, manually operated negotiation process conducted through its dedicated portal and live chat rather than email-only channels. Victims are provided access to file-browsing views of sampled stolen data to validate claims and maintain pressure. The group applies staged escalation, including partial disclosure ahead of full publication, and has built a distinct pressure mechanism — its journalist early-access program — that is not commonly seen among comparable extortion groups.
Leak Site and Infrastructure Analysis
World Leaks operates a TOR-based leak ecosystem centered on a single primary leak site paired with a separate negotiation portal and journalist portal, rather than distributed file servers. The leak site presents a searchable company directory with revenue, employee count, and stock-ticker metadata alongside view counters intended to amplify visibility-driven pressure.
The platform includes a file-explorer interface allowing browsing of individual files within a disclosed dataset rather than requiring bulk archive download, and recent updates have added HTTP Range header support for resumable downloads and compression support for bandwidth efficiency.
The ecosystem includes:
-
Leak Site (TOR): Displays victim listings, disclosure status, and file-browsable datasets
-
Negotiation Portal (TOR): Live chat, payment tracking, and sample file access
-
Insider Journalist Portal (TOR): Grants media early access to disclosures ahead of public release
-
Affiliate Panel: Target registration and distribution of the exfiltration tool to partners
Key observations include:
- Distinct onion addresses for each of the four platform components
- A searchable, filterable file index observed on at least one disclosed dataset exceeding 1.2 TB across 858,000+ files
- Public "All" vs. "Published" disclosure-state separation for listed victims
- A recurring practice of removing victim entries shortly after sample publication, typically indicating active negotiation or payment
Overall, World Leaks' infrastructure reflects a centralized, reputation-amplifying exposure model, where the journalist early-access mechanism and negotiation-portal design distinguish it from groups relying on distributed file servers and manual messaging alone.
NPCIL / Kudankulam Nuclear Power Project Exposure
In mid-July 2026, World Leaks disclosed a large dataset attributed to Reliance Infrastructure, the EPC contractor responsible for common-services Balance of Plant (BoP) work on Units 3 and 4 of the Kudankulam Nuclear Power Project (KKNPP) in Tamil Nadu, India.

The exposed data originated from a server belonging to Reliance Infrastructure but hosted by Yotta Data Services Pvt. Ltd., a third-party Indian data-centre provider, within an isolated private-cloud environment dedicated to that customer. Yotta stated its security monitoring detected suspicious activity on the affected server on May 29, 2026, and that the suspicious process was terminated immediately, preventing ransomware execution on that host. Yotta further stated there is no evidence of impact to any other customer environment or to its shared cloud platforms, and that no lateral movement beyond the single server was observed on its side. Reliance Infrastructure was informed of claims of a data breach by the threat actor at the end of June 2026, roughly a month after Yotta's internal detection, and has directed Yotta to conduct a full investigation.
Independent review of the group's leak-site file explorer identified approximately 19,000 files (roughly 14.3 GB) specifically matching KKNPP-related search terms, out of a much larger disclosed Reliance dataset totaling approximately 1.2 TB across 858,000+ files. The material does not appear to relate to the reactors' core nuclear systems, which are supplied by a separate foreign technical partner. It reportedly includes engineering drawings for ventilation, cooling, and common-services buildings; vendor and sub-vendor approval lists; multi-year monthly progress reports; correspondence on extension-of-time requests and change proposals; an insurance policy reportedly valued in the hundreds of millions of dollars covering acts of terrorism against the reactor units; and HR, finance, and administrative records.
The plant operator has characterized the exposed material as pertaining only to conventional common-service facilities typical of any thermal power plant, unrelated to nuclear safety or security systems. Based on available reporting, this is a data exfiltration and threatened-publication event rather than a confirmed encryption event: Yotta's own account frames the activity as a suspected ransomware execution attempt that was interrupted before completing, while the material that ultimately surfaced publicly reflects the exfiltration component of the intrusion. Even absent core reactor system exposure, drawings, vendor lists, and facility layouts of this kind can in principle help map a plant's support infrastructure and identify weaknesses in its security chain.
Recent Indian Targeting Trend
World Leaks' actively targeting Indian entities has escalated sharply in mid-2026, forming a discernible regional cluster rather than isolated opportunistic hits.

|
Entity |
Sector |
Notes |
|
Tata Electronics |
Electronics manufacturing (Apple/Tesla supplier) |
~630 GB / 204,000+ files; reportedly included supplier-mapping documents, quality inspection standards, and third-party OEM drawings marked trade-secret |
|
Reliance Infrastructure (KKNPP, via Yotta-hosted server) |
Critical infrastructure / nuclear EPC contractor |
~1.2 TB / 858,000+ files disclosed; ~19,000 files tagged to Kudankulam specifically |
|
RattanIndia Power |
Power generation |
Listed on leak site |
|
Apollo Pipes |
Industrial manufacturing |
Listed on leak site |
|
M1xchange |
Financial services |
Listed on leak site |
This is also the second Tata Group subsidiary affected by this actor lineage within roughly eighteen months, a separate Tata entity having been affected under the group's prior identity — raising a recurring supply-chain question for multinational OEMs sourcing from Indian tier-one and tier-two suppliers, and for critical-infrastructure projects relying on third-party-hosted contractor infrastructure.
RANSOM NOTE

MITRE ATT&CK TTPs
|
Tactic |
Technique ID |
Technique Name |
|
Reconnaissance |
T1598 |
Phishing for Information |
|
Initial Access |
T1078.002 |
Valid Accounts: Domain Accounts |
|
Initial Access |
T1133 |
External Remote Services |
|
Initial Access |
T1190 |
Exploit Public-Facing Application |
|
Initial Access |
T1566 |
Phishing |
|
Execution |
T1059.001 |
Command and Scripting Interpreter: PowerShell |
|
Execution |
T1059.003 |
Command and Scripting Interpreter: Windows Command Shell |
|
Execution |
T1053.005 |
Scheduled Task/Job: Scheduled Task |
|
Persistence |
T1547.001 |
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
|
Persistence |
T1078.002 |
Valid Accounts: Domain Accounts |
|
Stealth |
T1027.013 |
Obfuscated Files or Information: Encrypted/Encoded File |
|
Stealth |
T1036.005 |
Masquerading: Match Legitimate Resource Name or Location |
|
Stealth |
T1070 |
Indicator Removal |
|
Defense Impairment |
T1685 |
Disable or Modify Tools |
|
Credential Access |
T1003 |
OS Credential Dumping |
|
Credential Access |
T1552.001 |
Unsecured Credentials: Credentials In Files |
|
Credential Access |
T1555 |
Credentials from Password Stores |
|
Discovery |
T1083 |
File and Directory Discovery |
|
Discovery |
T1135 |
Network Share Discovery |
|
Lateral Movement |
T1021.002 |
Remote Services: SMB/Windows Admin Shares |
|
Collection |
T1005 |
Data from Local System |
|
Collection |
T1039 |
Data from Network Shared Drive |
|
Collection |
T1074.001 |
Data Staged: Local Data Staging |
|
Collection |
T1213 |
Data from Information Repositories |
|
Command and Control |
T1071.001 |
Application Layer Protocol: Web Protocols |
|
Command and Control |
T1090.003 |
Proxy: Multi-hop Proxy |
|
Exfiltration |
T1020 |
Automated Exfiltration |
|
Exfiltration |
T1041 |
Exfiltration Over C2 Channel |
|
Exfiltration |
T1048 |
Exfiltration Over Alternative Protocol |
|
Exfiltration |
T1537 |
Transfer Data to Cloud Account |
|
Exfiltration |
T1567.002 |
Exfiltration Over Web Service: Exfiltration to Cloud Storage |
Indicators of Compromise (IOCs)
|
Type |
IOC Value |
|
IP |
193.149.180[.]50 |
|
IP |
193.161.193[.]99 |
|
IP |
51.15.109[.]222 |
|
Domain |
Smtlawyers[.]ca |
|
URL |
Hxxps[://]www[.]realtaxcanada[.]com/en/home-en/ |
|
SHA-256 |
7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a |
|
SHA-256 |
94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73 |
|
SHA-256 |
c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44 |
|
SHA-256 |
e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d |
|
SHA-256 |
e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96 |
|
SHA-256 |
eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577 |
|
Leak Site (TOR) |
hxxps://worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion |
|
Negotiation Portal (TOR) |
hxxps://vw6vklsuotptwdbiwqfvd7y4b57wdbfm6ypxduzzgbt62snti6jm76yd[.]onion |
|
Insider Journalist Portal (TOR) |
hxxps://3jguvp6xhyypdjgxhxweu4zklse66v3awjj2zljpftcjyeoimepnwtyd[.]onion |
|
Secondary Contact Domain |
hxxps://shmlxznhxt4wogoo7m5iidw365ocbauwbnmb6rxcxtvlqumlinxqvhqd[.]onion |
Mitigations & Recommendations
Initial Access Hardening
- Enforce multi-factor authentication (MFA) across all external access points
- Continuously discover and monitor exposed assets, shadow IT, and external attack surface risks using CyberXTron ShadowSpot
- Monitor for compromised credentials and exposed identities using CyberXTron DarkFlash
Identity & Credential Protection
- Rotate credentials and OTP seeds for any device suspected of prior compromise, even after patching
- Implement strict least-privilege access controls across all system
Network Security & Lateral Movement Control
- Segment networks to isolate critical systems, engineering data, and sensitive vendor environments
- Monitor internal access behavior for signs of unauthorized lateral movement or privilege misuse
- Improve network visibility and investigation capabilities using CyberXTron MCP (Managed Cyber Platform)
Endpoint Protection & Threat Monitoring
- Deploy EDR/XDR solutions focused on behavioral detection rather than signature-based alerts
- Monitor command execution, scripting activity, and abnormal system behavior
- Enhance real-time detection and response using CyberXTron ThreatBolt
Data Protection & Exfiltration Prevention
- Monitor outbound traffic for large or unusual data transfers, especially to TOR-related or unknown cloud infrastructure
- Implement Data Loss Prevention (DLP) controls tuned for volume and destination, not just content
- Classify and minimize sensitive engineering, supplier, and PII datasets; enforce retention limits
- Identify leaked credentials, exposed data, and underground exposure using CyberXTron DarkFlash
External Exposure & Leak Monitoring
- Continuously monitor dark web and leak sites for early signs of data exposure using CyberXTron DarkFlash
- Track unauthorized publication of organizational data and misuse of brand identity
- Identify unknown internet-facing assets, third-party exposures, and misconfigured services using CyberXTron ShadowSpot
Third-Party & Hosting/Supply Chain Risk
- Require third-party data-centre and hosting providers to provide documented incident-detection SLAs and mandatory customer notification timelines
- Audit EPC-contractor and vendor data-handling practices for critical-infrastructure projects
- Assess downstream exposure whenever a hosting provider or contractor discloses suspicious activity, even if initially described as contained
Incident Response & Extortion Readiness
- Maintain separate playbooks for data-exposure-only incidents versus ransomware-encryption incidents, given this actor's demonstrated capability for both
- Retain security logs 90+ days to counter log-suppression techniques
- Capture forensic disk images before remediation on suspected rootkit-affected devices
- Accelerate investigation and response using CyberXTron MCP and XTron AI
Conclusion
World Leaks represents the current identity of a lineage running through Hunters International, reflecting a deliberate strategic pivot toward a data-centric extortion model where the primary objective is extraction and controlled exposure of sensitive information rather than system disruption through encryption. Its operational structure — a centralized TOR-based leak ecosystem, a dedicated negotiation portal, and a journalist early-access program — demonstrates a more coordinated approach to maximizing pressure through visibility and staged disclosure than is typical among comparable extortion groups. The group's escalating focus on Indian manufacturing, electronics, and critical-infrastructure-adjacent contractors, culminating in the Kudankulam-linked disclosure, highlights both operational reach and a forming regional targeting pattern. At a strategic level, World Leaks reflects an evolving threat landscape where data itself is the primary monetized asset, while its inherited encryption capability means organizations should not treat the "extortion-only" positioning as a fixed operational limit. This trend underscores the growing importance of data protection, exposure monitoring, third-party risk management, and identity security as organizations face increasing risk from adversaries prioritizing data exploitation over traditional ransomware deployment.